Terms & Privacy
Last updated: [FILL: publication date] · Operated by [FILL: legal entity name — e.g. your sole-trader name or Ltd company + company number]
Every [FILL: …] marker below needs your real facts. This is an honest scaffold structured for a compliance product, not finished legal copy — for a product whose whole value is trust, have a lawyer review the liability and data sections before this goes live. Nothing here should be treated as legal advice.
1 · What OnchainDiligence is (and is not)
OnchainDiligence returns factual checks against public and third-party data sources, each accompanied by a cryptographically signed attestation recording what was checked and when. It is a tool to support your compliance process. It is not legal advice, not a compliance or sanctions determination, and not a substitute for your own compliance program, judgment, or professional advice.
Specifically, a result from OnchainDiligence means "this is what the underlying data source returned at this moment, and here is signed proof the check ran." A "clean" result is not a guarantee that a counterparty is safe, lawful, or sanctions-free; a match is a candidate to investigate, not a finding. You remain solely responsible for the decisions you make using these checks, including any decision to transact, onboard, block, or report.
Coverage is bounded and disclosed. Sanctions screening reflects the coverage of the Chainalysis on-chain sanctions oracle (OFAC SDN, EU, and UN designated addresses); name screening reflects the public OFAC SDN list (primary names and strong aliases, per OFAC guidance — weak aliases are not screened); UK company data reflects Companies House open data; US public-company data reflects SEC EDGAR (SEC-registered public companies and funds only — a "not found" means "not an SEC filer", not "not a real company"). A gap in a data source is disclosed in the response, never hidden or guessed around.
2 · Terms of Service
2.1 Acceptance
By accessing or using the OnchainDiligence API, SDK, website, or any related service (the "Service"), you agree to these Terms. If you use the Service on behalf of an organisation, you represent that you have authority to bind it.
2.2 The Service
The Service provides pay-per-call compliance checks (sanctions screening, OFAC name screening, UK and US company verification, and combined diligence), signed attestations over each result, optional on-chain anchoring of attestation hashes, and — where offered — continuous re-screening and alerting. Checks are paid per call over the supported payment rails ([FILL: confirm current rails — MPP on Tempo (pathUSD) and x402 on Base (USDC)]). The Service is keyless where stated: no account is required to make an individual paid call.
2.3 Acceptable use
You agree not to:
- use the Service to unlawfully discriminate against, harass, or harm any person;
- represent an OnchainDiligence result as a definitive legal or regulatory determination to any third party;
- use the Service as your sole or final compliance control where law or regulation requires independent judgment or human review;
- attempt to overwhelm, reverse-engineer for abuse, or circumvent the rate limits or payment mechanism of the Service;
- use the Service in any way that violates applicable sanctions, export-control, anti-money-laundering, or data-protection law.
2.4 Payment
Paid checks are settled per call at the prices shown at the time of the call. Because settlement is on-chain and non-custodial, [FILL: your refund position — e.g. "payments for completed checks are non-refundable; if a check fails before returning a result, no payment is captured"]. OnchainDiligence never takes custody of your funds.
2.5 Availability
The Service depends on third-party upstream data sources and public infrastructure. It is provided on an "as available" basis; upstream outages are surfaced honestly on the status page rather than masked. [FILL: whether you offer any uptime commitment / SLA — for subscription tiers you may; for pay-per-call likely "no SLA"].
2.6 Changes
These Terms may be updated; the "last updated" date reflects the current version. Material changes will be [FILL: how you'll notify — e.g. "posted here and, for subscribers, emailed"]. Continued use after a change constitutes acceptance.
2.7 Governing law
These Terms are governed by the laws of [FILL: governing jurisdiction — e.g. England and Wales], and disputes are subject to the [FILL: courts — e.g. exclusive jurisdiction of the courts of England and Wales].
3 · Liability — "what happens when an attestation is wrong"
This section answers the question a compliance officer will ask first, in writing, plainly.
An attestation proves that a specific check ran against a specific data source at a specific time and returned a specific result. That is exactly what the signature covers, and no more. An attestation does not assert that the underlying data was complete, current, or correct — only the data source can speak to that — and it does not convert the result into a determination.
A result can be "wrong" in the everyday sense in ways outside our control: an upstream list may lag a real-world designation, a name may match or miss due to transliteration or aliasing, an address may be freshly sanctioned between one check and the next, or a data source may be temporarily degraded. Where a source is unavailable, the Service discloses that rather than substituting a guess.
Accordingly, and to the maximum extent permitted by law:
- the Service is provided without warranty that any result is complete, accurate, current, or fit for a particular regulatory purpose;
- OnchainDiligence is not liable for losses arising from your reliance on a result as if it were a determination, from an upstream data source's error or omission, or from your own compliance decisions;
- to the extent any liability cannot be excluded, it is limited to [FILL: liability cap — commonly the greater of fees paid in the preceding N months, or a fixed sum. Get legal input on this number; it is the single most important commercial term on the page];
- nothing in these Terms excludes liability that cannot lawfully be excluded (for example, [FILL: jurisdiction-specific carve-outs — e.g. death or personal injury caused by negligence, or fraud, under English law]).
We give you a fast, signed, verifiable record that a check happened and what it said. Deciding what to do about it is your compliance program's job, not ours — and the signed record is designed precisely so that, later, you can prove you checked.
4 · Privacy Policy
4.1 The short version
Checks are keyless and results are never cached. On-chain anchoring stores only the keccak256 hash of an attestation signature — never a wallet address, name, company, or result — so nothing on-chain reveals who was screened or what the answer was.
4.2 Who is the data controller
The data controller for this Service is [FILL: legal entity + registered/contact address]. For UK/EU users, this Policy is intended to align with the UK GDPR and the Data Protection Act 2018. [FILL: confirm whether you have any establishment in the EU or process EU-resident data at a scale triggering an EU representative requirement].
4.3 What we process, and why
The inputs you submit to a check (for example a wallet address, a name to screen, or a company number) are processed solely to perform that check and return a signed result. [FILL: state your true retention position for check inputs — e.g. "check inputs are processed in memory to serve the request and are not stored after the response is returned; results are not cached." If any logging retains inputs, say so honestly and for how long.]
- Check inputs — [FILL: retained? for how long? or transient only?]
- Operational logs — [FILL: what your host (Vercel) and you log — e.g. request timestamps, status codes, IP for rate-limiting/abuse-prevention; retention period]
- Payment metadata — on-chain payments are public by nature of the blockchain; [FILL: what, if anything, you record off-chain about payments]
- Subscription / contact data (if you contact us or subscribe) — [FILL: email and any details you collect via lead capture / billing; processor e.g. Stripe/Lemon Squeezy]
4.4 Legal bases (UK/EU GDPR)
[FILL: map each processing purpose to a lawful basis — typically: performing the check = contract/legitimate interest; abuse-prevention logging = legitimate interest; subscriber comms = contract/consent. Confirm with legal input.]
4.5 Sub-processors and third parties
The Service relies on third parties to function. These currently include [FILL: list — e.g. Vercel (hosting), the Chainalysis sanctions oracle, OFAC/US Treasury data, UK Companies House, SEC EDGAR, Coinbase CDP (x402 settlement), and any Postgres host / payment processor you add]. Public data sources (OFAC, Companies House, SEC EDGAR) are queried to perform checks; we do not sell or share your inputs with them beyond what the query itself requires.
4.6 International transfers
[FILL: note that some processors (e.g. US-based hosting/data sources) involve transfers outside the UK/EEA, and the safeguard relied on — e.g. UK IDTA / EU SCCs / adequacy. Get legal input.]
4.7 Your rights
Subject to applicable law, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. Because the Service is largely keyless and non-retaining, [FILL: honestly note what you can and cannot action — e.g. "for transient check inputs there is typically nothing retained to access or delete"]. To exercise a right, contact us below. You also have the right to complain to the [FILL: supervisory authority — e.g. the UK Information Commissioner's Office (ICO)].
4.8 Cookies
[FILL: true cookie position. If the site sets no non-essential cookies and no analytics, say exactly that — it is a genuine trust signal and avoids needing a consent banner. If you add analytics later, update this and add a banner.]
5 · Contact
Questions about these Terms or your data: support@onchaindiligence.com. Security matters: security@onchaindiligence.com. [FILL: postal contact address if required for your entity type / GDPR].